Skip to content

feat(proofs): Evidence Mode foundations — Agda library + golden vectors (#7) - #78

Merged
hyperpolymath merged 4 commits into
mainfrom
arena/01a0db52-metamanifold-webui
Sep 26, 2026
Merged

hyperpolymath merged 4 commits into
mainfrom
arena/01a0db52-metamanifold-webui

Conversation

@arena-ai-coding-agent

Copy link
Copy Markdown

Summary

First slice of #7 (Full Evidence Mode): the formal foundations. What a residual, an evidence-refined candidate set, a warrant token and a presence verdict are — proved, executable inside Agda, and pinned across implementations.

The reference explorer's own footer admits its signed JavaScript model has no proved extraction correspondence with any proof. This PR closes exactly that gap:

  • L0 — abstract semantics (Evidence.Residual, Echo, Warrant): Candidate observe r E = Σ W ((observe w ≡ r) × E w); Holds quantifies over all candidates, not the case's chosen witness; actual-world-sound is the honesty boundary (a warranted claim about candidates says nothing about reality until the actual world is shown admissible); Echo/AvecFibre fibre semantics with the total-space factorisation (the licence for storing rows as (observed, witnesses) pairs); Warrant/Epi/SoundWarrant with epi-does-not-give — a warrant token is not truth, proved by countermodel.
  • L1 — signed finite model (Evidence.Signed): signed-integer-v1 as ℕ offsets, so every predicate is decidable and the model runs inside Agda; enumeration proved sound (listed ⇒ satisfies) and complete (satisfies ∧ b ≤ 6 ⇒ listed).
  • L2 — decision procedures (Evidence.Decision): the exact computation the server routes and the residual explorer run, proved to decide the candidate semantics: entailed ⇒ Present holds; refuted ⇒ Absent holds; unresolved ⇒ neither (explicit witnesses both ways); inconsistent ⇒ no inhabited case — an empty candidate set does not make claims vacuously true. The five reference presets land as computed, proved terms (e.g. present-without-identification: presence without a value).
  • L3 — the pin: 546 golden vectors (proofs/vectors/evidence_vectors.json, regenerate with scripts/gen_evidence_vectors.py) covering all four verdicts and both identification outcomes, for Julia and bun test stacks to consume so Agda/Julia/TS are bound to one truth.

Negative control: reject/IdentificationWithoutUniqueness.agda — reporting an identified value from a mere presence verdict (the UI bug Evidence Mode exists to prevent) must fail to type-check, and does.

Changes

  • proofs/agda/MetaManifold/Evidence/ — six new stdlib-free modules (only Agda.Builtin.*, so they check under any Agda ≥ 2.6.4.3)
  • proofs/agda/MetaManifold/All.agda, proofs/agda/README.md — suite integration
  • proofs/agda/reject/IdentificationWithoutUniqueness.agda — new negative control
  • scripts/gen_evidence_vectors.py + proofs/vectors/evidence_vectors.json — the golden-vector pin
  • docs/formal/evidence-verification.md — layering, verdict theorems, theorem-to-test map, and what is deliberately not proved

Verification

  • All six modules type-check clean (exit 0, no errors) under Agda 2.7.0.1, --safe --without-K.
  • check-proofs.sh guard logic replicated locally on all 17 modules: no postulates/holes/escape flags; pragma present.
  • Reject control fails with the error its -- EXPECT: line states.
  • scripts/check-spdx.sh: OK (327 files).
  • Vectors regenerate byte-identically (546 cases).
  • The full All.agda suite check runs in CI under the estate pin (Agda 2.6.4.3 + stdlib 2.1); the Evidence half is stdlib-free by construction, so toolchain drift cannot affect it.

Scope note

The UI layer of #7 (avec_fibre editor, fibre visualizer, residual explorer, warrant editor, provenance logging, DANGER banner) follows in later stacks on top of these foundations. Refs #7.

Note on CI

File-based workflows have been failing repo-wide with startup_failure since 2026-09-25 (diagnosed in #76 as settings/platform-side). If checks show that, it is unrelated to this change.

hyperpolymath and others added 3 commits September 26, 2026 15:30
…icts (#7)

## Summary

Lands the formal-foundations layer of Evidence Mode: what a residual,
an evidence-refined candidate set, a warrant token and a presence
verdict *are*, and a proof that the verdict computation the server
routes and the residual explorer run decides exactly the candidate
semantics. Closes the gap the reference explorer's own footer admits
("separately tested JavaScript, no proved extraction correspondence").

## Changes

- `MetaManifold/Evidence/{Prelude,Residual,Echo,Warrant,Signed,Decision}.agda`
  — L0 abstract semantics (Candidate fibres; Holds quantifies over ALL
  candidates; actual-world honesty; epi-does-not-give), L1 the signed
  finite model 'signed-integer-v1' as ℕ offsets with enumeration proved
  sound + complete, L2 verdicts computed and proved correct
  (entailed/refuted/unresolved/inconsistent), the five reference
  presets as computed proved terms.
- `All.agda` imports the six new modules (CI reachability gate).
- `reject/IdentificationWithoutUniqueness.agda` — negative control:
  reporting an identified value from a mere presence verdict must not
  type-check.
- `README.md` — module table rows + stdlib-free note (Evidence.* uses
  only Agda.Builtin.*, so it checks under any Agda ≥ 2.6.4.3).

## Verification

- All six modules type-check clean (Agda 2.7.0.1, --safe --without-K,
  exit 0, no output).
- check-proofs.sh guard logic replicated on all 17 modules: no
  postulates/holes/escape flags; --safe --without-K pragma present.
- reject control fails with `fst (fst c) != 8` as its EXPECT line states.
- `scripts/check-spdx.sh`: OK.
- Full All.agda run needs the estate toolchain (Agda 2.6.4.3 +
  stdlib 2.1); the Evidence half is stdlib-free by construction.

Issue tracking:
See also: #7

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
## Summary

546 golden cases (13 residuals × 7 noise bounds × 3 views × 2
zero-assumptions) that pin the signed finite model's answers —
candidate counts, presence verdicts, identified values — as data, so
Agda, Julia and TypeScript can be bound to one truth instead of three
agreeing-by-accident implementations.

## Changes

- `scripts/gen_evidence_vectors.py` — the durable encoding of the
  explorer semantics (validation, candidate enumeration, decide,
  identify); regenerates the JSON byte-identically.
- `proofs/vectors/evidence_vectors.json` — the generated pin; all four
  verdicts and both identification outcomes covered, plus the five
  reference presets.

## Verification

- Regeneration diff: identical (546 cases).
- Fields anchored in Decision.agda: candidate_count ↔ length,
  presence ↔ decide + the four theorems, identified_values ↔ values.

Issue tracking:
See also: #7

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Companion to verification-plan.md for the evidence library: the layer
table (abstract semantics → signed finite model → decision procedures
→ implementation seam), the four verdict theorems, the golden-vector
theorem-to-test map, and what is deliberately not proved (server/UI
code, beyond-the-grid, funext, general extraction).

Issue tracking:
See also: #7

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 93389df1-e9ed-4790-824f-51ad1063e46c

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit 770a614 into main Sep 26, 2026
1 check was pending
@hyperpolymath
hyperpolymath deleted the arena/01a0db52-metamanifold-webui branch September 26, 2026 15:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant